Threat actors are actively exploiting a critical remote code execution vulnerability in the WooCommerce Wholesale Lead Capture plugin, while separate flaws threaten users of The Events Calendar.
Key Points
- The WooCommerce Wholesale Lead Capture vulnerability, tracked as CVE-2026-27540, allows unauthenticated attackers to upload malicious PHP files via the "wwlc_file_upload_handler" AJAX action.
- Wordfence has blocked over 100,000 exploit attempts targeting the WooCommerce plugin, which affects all versions up to 2.0.3.1.
- The Events Calendar plugin, used by over 600,000 websites, contains two critical remote code execution flaws, CVE-2026-78159 and CVE-2026-78006.
- Exploitation of The Events Calendar vulnerabilities can lead to full site takeover, password resets, and arbitrary command execution on the underlying server.
- Developers have released patches for both plugins, and administrators are urged to update immediately to secure their WordPress environments.